Cross-site scripting in eLabFTW - #VU137350

 

Cross-site scripting in eLabFTW - #VU137350

Published: July 12, 2026


Vulnerability identifier: #VU137350
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary html into notifications.

The vulnerability exists due to cross-site scripting in the notification dropdown when rendering the profile fullname from action-request notifications. A remote user can update their profile fullname via the user profile API and trigger an action-request notification to inject arbitrary html into notifications.

User interaction is required for another authenticated user to view the notification dropdown.


Affected software

eLabFTW

Remediation

Install security update from vendor's website.

eLabFTW - update to 5.6.0

External References

Related Security Bulletins